If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: www.tssci-security.com - tssci security.

site address: tssci-security.com redirected to: www.tssci-security.com

site title: tssci security

Our opinion (on Friday 28 August 2026 0:03:31 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:
description=tssci-security - top secret/secure computing information;

Headings (most frequently used words):

burp, jython, web2py, api, decoding, and, tampering, protobuf, serialized, messages, in, key, as, initialization, vector, extending, with, pentesting, flex, is, vulnerable, getting, loading, the, search, categories,

Text of the page (most frequently used words):
the (65), you (26), burp (22), and (20), this (15), #jython (14), that (13), key (12), with (11), protobuf (11), can (10), extension (10), from (9), api (9), #web2py (9), message (9), security (7), other (7), code (7), like (7), for (7), what (7), also (6), find (6), have (6), when (6), aes_new (6), was (6), ptext (6), looks (6), proto (6), posted (5), using (5), applications (5), new (5), all (5), function (5), request (5), will (5), deserialize (5), application (5), messages (5), blog (4), search (4), marcin (4), thursday (4), post (4), into (4), python (4), flex (4), released (4), download (4), may (4), features (4), framework (4), time (4), any (4), not (4), z0q (4), mtext (4), quick (4), our (4), aes (4), protocol (4), out (3), how (3), make (3), over (3), 2013 (3), requests (3), console (3), response (3), after (3), next (3), should (3), see (3), then (3), running (3), plugins (3), their (3), which (3), used (3), data (3), vulnerable (3), exploit (3), ctext (3), 0x00 (3), 0x10 (3), 0x20 (3), 0x30 (3), brown (3), following (3), bytearray (3), ciphertext (3), insecure (3), tamper (3), here (3), comments (2), powered (2), disqus (2), please (2), view (2), tssci (2), entries (2), back (2), write (2), client (2), server (2), pentesting (2), adobe (2), tool (2), blazentoo (2), proxy (2), allowing (2), web (2), tools (2), through (2), february (2), some (2), right (2), could (2), specific (2), send (2), useful (2), interactive (2), allows (2), extender (2), object (2), various (2), information (2), header (2), list (2), extensions (2), need (2), provided (2), loading (2), latest (2), version (2), environment (2), users (2), still (2), others (2), take (2), last (2), year (2), more (2), are (2), overview (2), ability (2), return (2), hmac (2), pull (2), short (2), encrypt (2), user (2), crypto (2), testtesttesttest (2), way (2), xor (2), str (2), easily (2), secret (2), decrypted (2), def (2), fox (2), control (2), encryption (2), look (2), why (2), never (2), uncommon (2), made (2), even (2), easier (2), example (2), simple (2), initialization (2), vector (2), google (2), much (2), required (2), fields (2), know (2), about (2), manually (2), note (2), lucky (2), enough (2), protoc (2), decode_raw (2), serialized (2), decoder (2), type (2), raw (2), ever (2), reading (2), enable, javascript, 2006, 2015, work, windows, tech, 233, school, privacy, politics, phrack, day, people, news, lockpicking, linux, links, itsm, intelligence, hacking, defense, conferences, books, apple, categories, older, newer, march, 2010, sure, check, while, goes, remoting, calls, remote, custom, amf, entry, employer, along, called, exploits, insecurely, configured, blazeds, services, potentially, browse, internal, sites, gds, page, penetrating, intranets, future, dive, mean, feel, free, fork, contribute, added, click, context, menu, item, select, them, variable, accessible, items, additional, feature, tab, interact, variables, local, namespace, iterate, history, collecting, highlighting, commenting, contain, string, body, clicked, among, currently, loaded, haven, already, done, later, add, lib, burp_extender, first, get, standalone, writing, once, configure, 7beta1, getting, since, portswigger, develop, sorts, extend, myriad, ways, regardless, place, few, paragraphs, guide, setting, buby, plugin, multiple, simultaneously, exposes, provides, functionality, eases, developing, runtime, providing, pythonic, apis, automatic, reloading, configurations, updated, presented, nyc, similar, frameworks, provide, isec, partners, forum, filter, extending, been, keeping, master, patches, random, anytime, invoked, utilizes, secure, constant, validate, compare, merged, manner, across, codebase, did, appear, exploitable, pickled, session, cookie, authenticated, coincidentally, however, use, convenience, decrypting, most, likely, amongst, vulnerabilities, tend, crop, rolling, your, own, timing, attack, secure_dumps, b9561dc60a622f09f8cb49f47a30719a19ef66aa2ea6f7772a15e81b722830fbea38af2c1fdbbf6340e9707592aadfd4ce57b982597eb1e93cc311f25ea73b5d, b9561dc60a622f09f8cb49f47a30719a00000000000000000000000000000000b9561dc60a622f09f8cb49f47a30719ab9561dc60a622f09f8cb49f47a30719a, 54686520717569636b2062726f776e20520b27652be2f4a1c978b57c0967a34c200d165405101a171f4511061b121d54995b0b920f72351ee78e58f261226cce, returns, included, hexdumps, each, step, print, recover, decrypt, point, identify, 0x0, malformed, plan, feed, produced, zip, jumped, lazy, dog, attacker, perspective, being, fed, output, text, deduce, perform, demonstrates, mode_cbc, lambda, snip, import, cipher, let, construction, module, prior, merging, fixed, issue, gluon, utils, bad, well, email, 1996, david, wagner, explains, sci, crypt, mailing, developers, accidentally, purposefully, commit, passwords, supposed, remain, revision, github, these, same, easy, grep, kinds, patterns, especially, cryptographic, constructions, repositories, revealed, project, focus, secrets, rsa, private, keys, indexed, hopefully, testing, based, now, confirms, tampered, succesfully, reserialize, its, errors, occur, such, missing, alert, dialog, pop, letting, but, wait, better, comes, automatically, attempt, types, until, one, found, initialized, result, false, positives, person, addressbook, taken, defines, load, again, another, adding, protoburp, setmessage, getmessage, isenabled, looking, does, things, bit, differently, modifying, identifies, http, content, equal, decoded, start, off, tried, probably, yourself, buffer, encoding, set, screenshots, give, capable, necessity, wrote, would, decode, available, modify, specify, given, assessed, poked, uses, painstaking, whole, process, corresponding, crafting, via, tedious, don, resort, hand, otherwise, left, dumb, fuzzing, diving, itself, extracting, file, descriptor, reversing, format, generated, buffers, decoding, tampering, research, projects, home,


Text of the page (random words):
tssci security home about projects research decoding and tampering protobuf serialized messages in burp if you ve ever assessed or poked at an application that uses google protocol buffers you know how painstaking the whole process can be when you re lucky enough to have a corresponding proto crafting messages via generated api s is tedious when you don t you have to resort to reversing the protocol format by hand and or extracting the proto file descriptor out of the application otherwise you re left dumb fuzzing the protocol and never diving into the application itself out of necessity i wrote a burp extension that would decode raw protobuf messages even when a proto was not available after loading a proto the extension features the ability to modify and tamper with protobuf messages in my extension you can also manually specify what message type to deserialize a given protobuf message as you can download my extension at burp protobuf decoder the following set of screenshots should give you a quick overview of what it s capable of we start off with a view of what a simple raw protobuf message looks like in burp if you ve ever tried to tamper this right here you d probably find yourself reading and re reading protocol buffer encoding here s what that message looks like when decoded using protoc decode_raw another request that looks to be adding a serialized user object note the burp protobuf decoder extension identifies protobuf messages by an http content type request or response header equal to application x protobuf if the application you re looking at does things a bit differently have a look at modifying isenabled getmessage and setmessage of protoburp py and again what it looks like after protoc decode_raw if we re lucky enough to have a proto that defines what this message looks like we can load it from here find our addressbook proto taken from the protobuf example applications we can then manually deserialize the message as a person next time a request comes through the extension will automatically deserialize the message note an attempt will be made to deserialize as all types until one is found to deserialize with all required fields initialized this could result in some false positives that looks much better but wait how about we tamper it the extension will reserialize our message and we can send it on its way if any errors occur such as required fields missing an alert dialog will pop up letting you know and the response from the server confirms our message was tampered succesfully hopefully my extension will make testing protobuf based applications much easier from now on posted by marcin on thursday may 30 2013 in security web2py key as initialization vector it s not uncommon for developers to accidentally or purposefully commit passwords or other information supposed to remain secret into revision control it s also not uncommon to see rsa private keys indexed by google and github made it even easier to find secrets in the code with their new search features these same search features make it easy to grep the web for all kinds of insecure code patterns especially insecure cryptographic constructions for example a simple search for aes new in python code repositories revealed to me the web2py project was using the encryption key as the initialization vector iv which is the focus of this blog post why is this bad well in an email to the sci crypt mailing list back in 1996 david wagner explains why you should never do this let s take a look at the insecure construction in web2py s gluon utils module prior to merging my pull request that fixed this issue from crypto cipher import aes snip aes_new lambda key aes new key aes mode_cbc iv key 16 from an attacker s perspective in short if we can control the ciphertext being fed to this function and see the output of this function the decrypted text we can easily deduce the key used to perform the encryption the following code demonstrates this key testtesttesttest ptext the quick brown fox jumped over the lazy dog the quick brown fox def xor a b return bytearray x y for x y in zip a b def exploit ciphertext produced by web2py ctext bytearray aes_new key encrypt ptext our malformed ciphertext we plan to feed to web2py mtext ctext 16 4 mtext 16 32 0x0 16 if at any point we identify what the decrypted data is ptext bytearray aes_new key decrypt str mtext we can easily recover the secret key used print key r str xor ptext 16 ptext 32 48 running this exploit returns the following i ve included hexdumps at each step of the way exploit ctext b9561dc60a622f09f8cb49f47a30719a19ef66aa2ea6f7772a15e81b722830fbea38af2c1fdbbf6340e9707592aadfd4ce57b982597eb1e93cc311f25ea73b5d 0x00 b9 56 1d c6 0a 62 2f 09 f8 cb 49 f4 7a 30 71 9a v b i z0q 0x10 19 ef 66 aa 2e a6 f7 77 2a 15 e8 1b 72 28 30 fb f w r 0 0x20 ea 38 af 2c 1f db bf 63 40 e9 70 75 92 aa df d4 8 c pu 0x30 ce 57 b9 82 59 7e b1 e9 3c c3 11 f2 5e a7 3b 5d w y mtext b9561dc60a622f09f8cb49f47a30719a00000000000000000000000000000000b9561dc60a622f09f8cb49f47a30719ab9561dc60a622f09f8cb49f47a30719a 0x00 b9 56 1d c6 0a 62 2f 09 f8 cb 49 f4 7a 30 71 9a v b i z0q 0x10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x20 b9 56 1d c6 0a 62 2f 09 f8 cb 49 f4 7a 30 71 9a v b i z0q 0x30 b9 56 1d c6 0a 62 2f 09 f8 cb 49 f4 7a 30 71 9a v b i z0q ptext 54686520717569636b2062726f776e20520b27652be2f4a1c978b57c0967a34c200d165405101a171f4511061b121d54995b0b920f72351ee78e58f261226cce 0x00 54 68 65 20 71 75 69 63 6b 20 62 72 6f 77 6e 20 the quick brown 0x10 52 0b 27 65 2b e2 f4 a1 c9 78 b5 7c 09 67 a3 4c r e x g l 0x20 20 0d 16 54 05 10 1a 17 1f 45 11 06 1b 12 1d 54 t e t 0x30 99 5b 0b 92 0f 72 35 1e e7 8e 58 f2 61 22 6c ce r5 x a l key testtesttesttest is web2py vulnerable in short no the manner in which aes_new was used across web2py s codebase did not appear to be exploitable web2py was using this to encrypt pickled session data in a cookie in secure_dumps and authenticated with an hmac which coincidentally was also vulnerable to a timing attack however applications that use aes_new as a convenience function for decrypting data provided by the user are most likely vulnerable amongst other vulnerabilities that tend to crop up when rolling your own crypto if you ve been keeping up with web2py s master my merged pull request patches the aes_new function to return a random iv anytime it is invoked and utilizes the more secure constant time compare function to validate hmac s posted by marcin on thursday february 21 2013 in security extending burp with jython burp api last year i released the jython burp api a plugin framework to burp that allows running multiple plugins simultaneously exposes an interactive jython console provides filter like functionality and eases developing plugins at runtime by providing more pythonic apis and automatic code reloading for when code or configurations are updated i presented an overview of my framework at an isec partners forum in nyc last year others have released similar frameworks that also provide the ability to write burp extensions in jython since then portswigger released a new burp extender api allowing users to develop all sorts of plugins and extend burp s various tools in a myriad of ways regardless i still find my framework and others like buby still have their place i d like to take the next few paragraphs to guide users on setting up the jython burp api in their environment getting jython first we ll need to get the latest 2 7 standalone version of jython at the time of this writing the latest version is jython 2 7beta1 once you download jython configure burp s python environment loading the jython burp api if you haven t already done so download the jython burp api then all you need to do provided you re running burp 1 5 04 or later is add jython burp api lib burp_extender py as a python extension to burp after you ve clicked next you should see the extension among the list of other currently loaded extensions if any an additional feature you may find useful is an interactive jython console tab that allows you to interact with the burp extender object and any other variables in the local namespace i find it useful to iterate over requests in burp s proxy history collecting various information or highlighting commenting requests that may contain a specific header or string in the response body i added a right click context menu item so you could select specific requests and send them to the items variable accessible from the console in a future blog post i may dive into using some of the other features of the framework in the mean time please feel free to fork and contribute to the jython burp api posted by marcin on thursday february 14 2013 in security pentesting flex i ve posted an entry over on my employer s blog on penetrating intranets through adobe flex applications i ve also released a new tool along with it called blazentoo this tool exploits insecurely configured blazeds proxy services potentially allowing you to browse internal web sites you can download blazentoo from gds tools page also be sure to check out my other post from a while back pentesting adobe flex applications with a custom amf client this post goes into how to write a client using python to make remoting calls with a remote flex server posted by marcin on thursday march 18 2010 in security newer entries 1 older entries search categories apple 9 books 5 code 5 conferences 22 defense 42 hacking 35 intelligence 14 itsm 13 links 9 linux 16 lockpicking 1 news 29 other 18 people 17 phrack a day 3 politics 11 privacy 24 school 9 security 233 tech 44 windows 4 work 19 2006 2015 tssci security please enable javascript to view the comments powered by disqus blog comments powered by disqus
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)

    No Images


    Verified site has: 46 subpage(s). Do you want to verify them? Verify pages:

    1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-46


    Top 50 hastags from of all verified websites.

    Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

    Header

    HTTP/1.1 301 Moved Permanently
    x-amz-id-2 tpCMVwQ34TKP0dJ0FJkkaQcSMyVqgb1D5XZlA45rR3GSsMgG87K7Ntg9mQGXc/m6KX8AhmX3Dic=
    x-amz-request-id NY5T17JV1S0DQ2Z8
    Date Fri, 28 Aug 2026 00:03:32 GMT
    Location htt???/www.tssci-security.com/
    Content-Length 0
    Server AmazonS3
    Connection close
    HTTP/1.1 200 OK
    x-amz-id-2 IIGiPH2yWbqJnGYoRk0PpO7m0gqk0dtjoD98LP81ZL9gsvHp9IN2acyl5+783zC75/dayVkoxtJr+2waSxuBAuLoGL/yeQe7
    x-amz-request-id NY5SVS9HEMXE72ZX
    Date Fri, 28 Aug 2026 00:03:32 GMT
    Last-Modified Wed, 24 Jun 2015 14:32:55 GMT
    ETag a3c1f32a1870cd417c7252346050f8d7
    Content-Type text/html
    Content-Length 28604
    Server AmazonS3
    Connection close

    Meta Tags

    title="tssci security"
    http-equiv="Content-Type" content="text/html; charset=UTF-8"
    name="description" content="tssci-security - top secret/secure computing information"

    Load Info

    page size28604
    load time (s)0.562087
    redirect count1
    speed download50896
    server IP 16.15.237.177
    * all occurrences of the string "http://" have been changed to "htt???/"